E-mail bounce-back of email user didn't send

I've been seeing a few of these a week in our environment, for different users.

But what happens is someone will get an e-mail like this one below, but they don't have anything in their Sent Items (Outlook 2010 or OWA) on the date/time of the timestamp, so I'm not sure why they're getting it or where it could be coming from.

The first one - they need a 'from' address to send from. They are not going to use their own address and if they send a million emails from xyz@example.com this will get black listed before they even reach the end of the list.
So their get round is to use emails in the mailing list as 'from'. They send a small amount from address 1 and then move on. That person will then receive some bounce backs or some real mails saying 'go away' etc.
You can fake an email address VERY easily. The email comes from whatever name and email you put it from.

The second method is to use the 'bounce' emails as a method of sending.
If they find a server that bounces emails either because the person doesn't exist or because it looks like spam then they can use this to SEND spam to other people.
Say the company bounces the mail back (maybe even with attachments) if it doesn't know the name.
If the company is called 'example.com'
and I want to send you a spam to 'garryshape@ourcompany.com'

then I send an email saying :

To : no-body-here@example.com
From : garryshape@ourcompany.com
Body : Hi garryshape would you like some viag.......etc etc etc

The company then bounces this back to the from address which is really your address and they have just sent out a spam.

The cure - read up on filtering spam. You can set up DNS entries for your own domain that will only allow it to come from set IPs (like your mail servers) and you can filter incoming addresses by blacklist/whitelists or by keywords.

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Featured Post

Do you feel like you are taking up all of your time constantly visiting users’ desks to make changes to email signatures? Wish you could manage all signatures from one central location, easily design them and deploy them quickly to users? Well, there is an easy way!

In this video we show how to create an Accepted Domain in Exchange 2013. We show this process by using the Exchange Admin Center.
Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center.
Navigate to the Mail Flow >> Ac…

To show how to generate a certificate request in Exchange 2013. We show this process by using the Exchange Admin Center.
Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center.
Navigate to the Servers >> Certificates…